I'm new to issue level security, but I've got it working for the first time just now - yay!
I have two issue security levels:
- 'any logged in user' and this is set to any logged in user as you can imagine

- 'XYZ personnel only' and this is set to a Project Role 'XYZ personnel'
It seems to work:
- issues set to 'XYZ personnel only':
- cannot be viewed by a 'normal' user
- can be viewed by users with the Project Role 'XYZ personnel'
- So far so good...
But is it possible to configure issue level security so that:
- UserType-A can view issues set to 'XYZ personnel only' but cannot change the issue's security level
- UserType-B (e.g. Project Role 'Administrators') can both view the issues set to 'XYZ personnel only' and edit the security level on the issue
This possible?